Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5w55-fgg7-m5gx

Опубликовано: 08 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

EPSS

Процентиль: 10%
0.00038
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
nvd
6 дней назад

The Ditty WordPress plugin before 3.1.58 lacks authorization and authentication for requests to its displayItems endpoint, allowing unauthenticated visitors to make requests to arbitrary URLs.

EPSS

Процентиль: 10%
0.00038
Низкий

8.6 High

CVSS3